CiberLATAMbywhalemate

CVE-2026-76461 Hits Cisco Secure Email Gateway

Cisco confirmed active exploitation in Secure Email Gateway. The flaw can let attackers run commands as root through a crafted email.

Whalemate Labs · AI-assisted researchPublished:2 min read

Cisco confirmed active exploitation of CVE-2026-76461 in Secure Email Gateway, a critical SQL injection flaw that can let an unauthenticated remote attacker run commands with root privileges through a crafted email. The company issued fixes for affected branches and said there is no workaround.

Cisco confirmed that CVE-2026-76461 affects both physical and virtual versions of Cisco Secure Email Gateway, allows remote command execution as root, and is already being actively exploited. The flaw was disclosed in a critical advisory on September 14, 2026. It is triggered by a specially crafted email that carries malicious SQL statements, and there is no workaround.

What kind of flaw is CVE-2026-76461?

The vulnerability is described as an SQL injection issue in Cisco AsyncOS email parsing logic for Cisco Secure Email Gateway, with a CVSS severity score of 9.8 from Cisco and NIST. The NVD summarizes the impact chain as insufficient validation in parsing, arbitrary SQL execution, and possible command execution with root privileges.

Cisco published an advisory titled Cisco Secure Email Gateway SQL Injection Vulnerability and said the flaw affects both physical and virtual devices, regardless of configuration. It also released fixed versions for the affected branches.

How broad is the impact?

The scope is not limited to Secure Email Gateway. A joint notice from the Center for Internet Security also identified Cisco Secure Email and Web Manager among the affected products and warned that exploitation could lead to full device compromise.

The same CIS notice also listed additional fixed versions for Secure Email and Web Manager and said that one branch has no corrected release. In that case, the recommendation is to move to a supported branch.

What did other reports and agencies say?

CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog on September 14, 2026, and set a remediation deadline of September 17, 2026, for federal agencies. Independent coverage also reported that the vulnerability was added to CISA's KEV list.

Rapid7 said there was no public proof of concept at the time of publication and that attribution to a threat actor had not yet been established. CyberScoop reported that Cisco contacted customers of Secure Email Cloud where indicators of possible compromise were identified, and that the company had already deployed managed mitigations in those environments.

Security Today added that Cisco recommended reviewing email and network logs for suspicious activity, and preserving forensic evidence before rebuilding a compromised virtual machine. Feedly also said Cisco had warned Secure Email Cloud customers about malicious activity tied to the CVE.

Sources

View all